Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 363

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Washington scrambles to meet calls for AI guardrails while the window to act closes
Obama voices caution on AI, urges Democrats to tackle it, NYT says
A Fed hike next week seems certain after the latest inflation data. Here's what's ahead
Dark Matter: Everything Beautiful, Everything Terrible Show Only
Snowpiercer: A Single Trade Rewatch
Hallux Rigidus
A puzzle! How did this NZ fence catch fire?
Barista Oat Milk
Baker Hughes sees no slowdown in energy projects despite higher rates as AI buildouts stoke LNG demand
Anthropic's Amodei says China presents 'toughest dilemma' for his proposed AI slowdown